Enterprise and governance
Controls your IT and legal teams can approve
Engage gives your governance review an audit record nobody can edit through the product, connector credentials held under a key per customer, a documented API with signed webhooks, and a way to move over that keeps every opt-out.
Who can do what?
Roles are set up with the Purple team. The same permission check decides on a screen, for the AI team and over MCP, while each API key is limited by its scopes. People come from Purple's central identity, so joiners and leavers are managed in one place.
- Six system roles: Admin, Full access, Marketer (drafts but cannot send), Approver, Analyst and Data manager
- A Team screen lists every member from Purple's central identity with their role and where it came from, and the last Admin cannot lose Admin
- For Reviews, a site manager sees only their assigned venues, and other venues answer "not found"
What is recorded, and can it be edited?
Changes are written to an audit store at the moment they happen. The database itself refuses to change that store, so nobody can edit the record through the product.
- The database refuses edits, deletions and truncation of the audit store
- Before and after values for settings, senders, subscription groups, brand kits, API keys, webhook endpoints and integrations, plus exports, erasures and imports
- Each event is written in the same transaction as the action, so a rolled-back action leaves no row and a committed one always has one
Who approves what reaches a guest?
A signed-in person, never an API key or an outside AI tool. By default, anything the AI team stages stops for a single-use preview of the exact action, and an ad always needs a person to approve the exact campaign and spend. The AI team page has the detail.
- AI review replies to 1 or 2 star reviews, or to any review flagged as a risk, need the venue owner, the venue's escalation contact or an administrator
- No MCP or API key scope can send a campaign
Can brands and venues be kept apart?
Brands sit between the company and its venues, so each trading brand keeps its own content and senders. Guests stay with the company.
- A brand level between the company and its venues, taken from your Purple Portal groups where you have them, or set up by an Admin
- Content, senders, forms, offers and surveys can belong to a brand, and brand A cannot use brand B's sender
- Contacts are never brand-owned, because the company is one data controller
Can we move over without asking everyone again?
Yes, without asking everyone again. Import by CSV and attest the consent you hold, run both platforms side by side for a cycle, and rebuild journeys by hand. An opt-out stays an opt-out, whatever you import.
- CSV import asks the uploader to attest consent and name the channels it covers, and records who attested
- An import with older or undated evidence can never undo a guest's own opt-out
- The Mailchimp connector sends guests and consent out, and Mailchimp unsubscribes always come back and win
- Imported history shows on the timeline but starts no journey
- Journeys are rebuilt by hand, so nothing runs that you did not set up
Can our systems read and write Engage?
Yes, through a documented public API, signed webhooks, a scheduled warehouse export and an MCP server for AI tools. Each API key reaches only its own company and what its scopes name, at up to 600 requests a minute (300 for an MCP key).
- 31 paths covering contacts, tags, segments, journeys, campaigns, reports, activities, forms and webhook endpoints
- 14 scopes: a key needs at least one, is shown once and stored only as a hash, revocation is immediate, and no key can create keys, send a campaign directly or edit a journey
- Webhooks signed with HMAC-SHA256 so your receiver can reject anything older than 300 seconds, delivered at least once over six attempts, with an endpoint switched off after 20 consecutive failures and erased contacts never published
- A scheduled export of contacts, activities, transactions, reservations and stays to your own BigQuery, Snowflake or S3, optionally pseudonymized
- An MCP server with 14 read tools for your own AI agents, acting as the key's creator, where no scope can send
- Every URL you give Engage must be HTTPS and publicly routable, so a webhook cannot be pointed at your internal systems
How are credentials and data held?
Connector credentials sit in a vault under a key held for each customer, and production runs in two named Google Cloud regions. Engage claims no security certification of its own.
- Connector credentials encrypted under a key held for each customer and rotated every 90 days, and destroying the key makes stored copies unreadable
- Production in two Google Cloud regions, the Netherlands and Los Angeles, with email sent through the EU region by default
- Sender domains authenticated in DNS, and events from the email provider signed
Talk to Purple
Plan your governance review
Tell us who signs off a marketing platform in your business and what they need to see. We will take your IT and legal teams through the audit record, the API and how every opt-out survives the move.
- The audit record and how roles are set up, for your IT and legal teams
- API scopes, webhook signing and rate limits, for your developers
- A move-over plan that keeps every opt-out, run beside your current tools
Questions
Do you support SSO or hold SOC 2 or ISO 27001?
Not in Engage itself. People sign in through Purple's central identity, and Engage offers no single sign-on, SAML, SCIM or multi-factor sign-in of its own. No SOC 2 or ISO 27001 certification is claimed for Engage.
Where is my data held?
In two Google Cloud regions: the Netherlands and Los Angeles. Email goes through the EU region by default. EU-only residency is not offered.
Can one brand be kept away from another's data?
For content and senders, yes. Contacts belong to the company as one data controller, so contact-level separation between brands is not offered.
Is there an API, and what are the limits?
Yes: 31 paths, 14 scopes and 600 requests a minute per key, bulk jobs of up to 1,000 contacts, signed webhooks and a scheduled export to BigQuery, Snowflake or S3.
Bring IT and legal in early
Walk them through what the audit store records, the API scopes and how an opt-out survives a move. The free plan is listed at 500 Actions a month, with unlimited contacts.